Back to skill

Security audit

UAV Farm Health Index Map | 无人机农田健康指数图生成

Security checks for vulnerabilities and agentic risk

Overview

The skill is an agricultural media-analysis wrapper, but it also performs under-disclosed cloud identity creation, token storage, and remote history access tied to user media.

Install only if you are comfortable sending farm imagery or video, URLs, and identity-linked report queries to the lifeemergence.com services, and with the skill creating/reusing a workspace user database that may store API tokens. Review the publisher and service terms before using it with sensitive farm, location, or business data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Authenticated API access, identity creation/persistence, local file I/O, and environment detection materially affect privacy and security posture but are not reflected in the agricultural-analysis description. In context, this makes the skill more dangerous because users may upload potentially sensitive farm imagery without realizing it is tied to internal identities and handled by remote services.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: "smyx-uav-farm-health-index-map-analysis"
description: "Using multispectral or high-resolution RGB cameras mounted on agricultural UAVs to capture orthophotos or mosaics of farmland, AI models compute vegetation indices (e.g., NDVI, NDRE) and generate a farm health-index heatmap, where colors distinguish crop vigor (red = poor, yellow = medium, green = healthy). | 通过农业无人机平台搭载的多光谱或高分辨率RGB相机,采集农田的正射影像或拼接图,利用AI模型计算植被指数(如归一化植被指数NDVI、归一化红边指数NDRE等),生成农田健康指数热力图,用颜色区分作物长�

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes analysis of multispectral or RGB orthophotos/mosaics to compute vegetation indices and generate health heatmaps. However, the code explicitly requires a local or network video path and sends it as videoUrl, indicating a broader or different media-analysis workflow than the declared image/map-analysis purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The implementation materially deviates from the manifest: it performs generic video analysis and history listing rather than UAV farmland orthophoto or vegetation-index processing. This is dangerous because users and higher-level systems may trust the declared agricultural purpose while actually sending arbitrary media or identifiers to a different backend capability, creating scope mismatch, data handling surprises, and possible unauthorized collection or exfiltration of unrelated content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The User model stores identity fields plus token and open_token values for a skill whose declared purpose is farm-image health analysis. Unnecessary credential/token storage expands the attack surface and can lead to sensitive secret exposure if the local SQLite file is accessed, copied, or reused by unrelated components.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This utility file contains identity resolution, local user persistence, token handling, workspace inspection, and authenticated outbound API logic that are unrelated to UAV farm health-map analysis. The mismatch between declared skill purpose and actual capabilities greatly expands the attack surface and enables collection or use of user identity and credentials beyond what a farm imaging skill needs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code can silently call an external /sys/phoneLogin endpoint with register=1 and user identifiers, effectively auto-registering or logging in users without any obvious relationship to UAV crop-health analysis. This creates undisclosed account creation and identity transmission risk, and could bind users to external services or leak identifiers without informed consent.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares broad operational behavior involving shell execution, local file handling, network access, and environment usage, but does not scope or constrain those capabilities with explicit permissions metadata. In an agent ecosystem, missing tool-scope declarations increase the chance of unintended or excessive tool use, making review and policy enforcement harder.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The default trigger is broad enough to activate the skill for generic file-analysis requests, increasing the risk of unintended execution and unnecessary transmission of user files to backend services. In an environment with networked skills and automatic attachment handling, overbroad triggers can cause privacy-impacting misfires.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A long keyword list without scope limits can cause the skill to match loosely related conversations and automatically handle files or query historical reports unexpectedly. Because this skill also performs cloud/API operations and identity-linked history lookup, accidental triggering has elevated privacy and data-minimization consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill omits a clear warning that uploaded imagery and report queries are sent to cloud/API services, which weakens informed user consent and obscures data-flow risks. This is especially important here because the skill also links report retrieval to internal identity handling and remote history access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The method returns a fixed Chinese string for output content, with no indication that the user can choose or opt into this locale. Per the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes computing vegetation indices like NDVI/NDRE from agricultural UAV imagery, but the entrypoint accepts a pet_type argument with values cat, dog, and other, and mutates ConstantEnum.DEFAULT__PET_TYPE. This indicates the implementation is repurposed from a pet/media analysis workflow rather than a dedicated farmland health-index analyzer, creating a semantic mismatch between the claimed domain-specific functionality and the actual code interface.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The CLI help text says the tool generates farmland health-index maps from UAV imagery, yet the core implementation simply calls skill.get_output_analysis(input_path) and ignores api_url, api_key, output_level, and the documented NDVI/NDRE-specific processing steps. The inline/user-facing documentation therefore overstates or mischaracterizes what this file itself does compared with the actual behavior shown here.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
skills/smyx_common/scripts/config-dev.yaml:2